Smart Access Filters does not work for devices accessing via Secure Hub / Citrix Endpoint Management (XenMobile)
book
Article ID: CTX312402
calendar_today
Updated On:
Description
Smart Access Filters does not work for the ICA traffic originating from Secure Hub / Citrix Endpoint Management (XenMobile).
The Smart Access Filters work as expected for sessions launched via the NetScaler Gateway - Only Secure Hub / Citrix Endpoint Management (XenMobile) session are affected.
Resolution
For the VDA to be able to correctly apply the policies expected,
The "AGFarm" Key must match the Farm name used in the Smart Access Filter.
This Key is located in:
HKLM\Software\Policies\Citrix\<User ID>\Evidence

Once you obtain the Farm name from the Evidence Key,
Simply add the new Farm to your Smart Access Filter
-> Policies now applying for sessions via Secure Hub / Citrix Endpoint Management (XenMobile)
Problem Cause
As per: https://support.citrix.com/article/CTX220967
When a device is compliant, the XenMobile Server will forward a set of
X-Citrix-SmartAccess headers with the following information:
X-Citrix-SmartAccess-Farm -> The name of the XenMobile farm.
Citrix Endpoing Management is setting a Tag for the Farm name, which overwrites the Farm name that is used for NetScaler Gateway Connections,
As a result of this, the expected Farm name you entered for the Policy is incorrect -> no policies applied
Additional Information
https://docs.citrix.com/en-us/xenmobile/server/apps/smart-access-to-hdx-apps.html
https://support.citrix.com/article/CTX207440
https://support.citrix.com/article/CTX138110
Was this article helpful?
thumb_up
Yes
thumb_down
No